{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp04_retrieval_first_paired20_20260802","cell_id":"computability_boundary_mapping__ethnography_qualitative_methods","hypothesis_id":"H4","search_queries":["arbitrary data transformation scripts provenance preservation static analysis consent policy verification","information flow control data processing scripts consent purpose policy enforcement research","workflow transformation provenance verification model checking arbitrary programs","qualitative research software custom scripts consent metadata provenance export","official documentation policy as code data transformations provenance consent Open Policy Agent decision unknown","language based information flow security static analysis arbitrary programs sound incomplete survey primary research","data usage control provenance policy enforcement workflow transformations primary research","patent consent metadata transformation provenance policy compliance software"],"sources":[{"source_id":"H4C1","title":"Constraints of the PROV Data Model","publisher":"World Wide Web Consortium","url":"https://www.w3.org/TR/prov-constraints/","source_class":"STANDARD","claims_supported":["Defines decidable normalization, validity, and equivalence checks for formally represented provenance instances.","Explains that unrestricted logical-rule application need not terminate and secures termination by restricting the specified rules to a weakly acyclic class.","Its guarantee concerns provenance-document consistency, not semantic preservation by arbitrary transformation programs."]},{"source_id":"H4C2","title":"Language-Based Information-Flow Security","publisher":"IEEE Journal on Selected Areas in Communications / Cornell University","url":"https://www.cs.cornell.edu/andru/papers/jsac/sm-jsac03.pdf","source_class":"PRIMARY_RESEARCH","claims_supported":["Establishes that general program confidentiality is undecidable by reduction from divergence.","Describes conservative security type systems and control- and data-flow analyses for enforcing restricted information-flow properties.","Supports the proposed distinction between unrestricted exact verification and sound but incomplete static checking."]},{"source_id":"H4C3","title":"WFDU-net: A Workflow Notation for Sovereign Data Exchange","publisher":"SciTePress, DATA 2021","url":"https://www.scitepress.org/PublishedPapers/2021/105504/pdf/index.html","source_class":"PRIMARY_RESEARCH","claims_supported":["Provides design-time model checking of annotated data workflows against owner-defined usage policies.","Converts policies to temporal logic and enumerates modeled actions through a finite formal workflow representation.","Reports scope limitations, including unsupported temporal obligations and inability to validate partial sections after policy changes."]},{"source_id":"H4C4","title":"Deep Enforcement: Policy-based Data Transformations for Data in the Cloud","publisher":"IBM Research","url":"https://research.ibm.com/publications/deep-enforcement-policy-based-data-transformations-for-data-in-the-cloud","source_class":"PRIMARY_RESEARCH","claims_supported":["Couples governance policies directly to compliant data transformations in storage systems.","Covers transformations ranging from redaction to differential-privacy mechanisms and supports inline or offline execution.","Closely overlaps policy-aware routing of transformation operations but does not claim universal verification of arbitrary scripts."]},{"source_id":"H4C5","title":"Data Flow Control: Data Safety Policies for AI Agents","publisher":"arXiv / Columbia University research","url":"https://arxiv.org/abs/2606.05679","source_class":"PRIMARY_RESEARCH","claims_supported":["Formalizes provenance-sensitive safety policies over tuple-level flows and enforces them through query rewriting.","Uses a declarative policy language restricted to SQL-92 queries across multiple relational database engines.","Demonstrates an existing restricted-language path to guaranteed policy enforcement inside data pipelines."]},{"source_id":"H4C6","title":"Open Policy Agent Documentation","publisher":"Open Policy Agent / Cloud Native Computing Foundation","url":"https://www.openpolicyagent.org/docs","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","claims_supported":["Implements pre-operation policy evaluation over structured inputs using the declarative Rego language.","Separates policy decision-making from enforcement and permits structured decisions beyond Boolean allow or deny.","Shows established policy-as-code practice, including an undefined result when evaluation produces no answer."]},{"source_id":"H4C7","title":"QualBuddy — Local-first Qualitative Research Software","publisher":"QualBuddy","url":"https://qualbuddy.com/","source_class":"COMMERCIAL_FIRST_PARTY","claims_supported":["Supports transcription, pseudonymization, coding, source-linked extracts, and export for qualitative research.","Preserves source and line references and keeps pseudonym mappings separate from exports.","Explicitly disclaims guaranteed anonymization and leaves ethics and output checking to researchers, supporting the problem weakly but not evidencing universal-clearance claims."]},{"source_id":"H4C8","title":"Verifying Workflow Processes: A Transformation-based Approach","publisher":"Eindhoven University of Technology / Software and Systems Modeling","url":"https://research.tue.nl/en/publications/verifying-workflow-processes-a-transformation-based-approach/","source_class":"PRIMARY_RESEARCH","claims_supported":["Transforms workflows with explicit semantics into equivalent Petri nets for design-time verification.","Demonstrates the established practice of regaining verifiability through a formally restricted workflow model.","Does not address consent, qualitative context, or guarantee-labeled fallbacks for unrestricted transformation code."]}],"proximity":"ADJACENT_PRIOR_ART","closest_analogues":[{"name":"WFDU-net usage-policy workflow verification","similarity":"Checks data-processing workflows against usage restrictions at design time using model checking, closely matching the proposed pre-installation gate and consent-policy concern.","remaining_difference":"It verifies a finite annotated workflow model rather than arbitrary qualitative transformation code and does not route unsupported programs among explicitly labeled fallback modes.","source_ids":["H4C3"]},{"name":"Data Flow Control and Deep Enforcement","similarity":"Both embed provenance- or governance-sensitive restrictions into data transformations instead of relying on post-hoc testing.","remaining_difference":"They enforce policies in restricted SQL or storage architectures and do not publish an unrestricted-program impossibility boundary or a multi-mode qualitative-script clearance protocol.","source_ids":["H4C4","H4C5"]},{"name":"Language-based information-flow verification","similarity":"Already combines a formal undecidability boundary for general semantic security with conservative static analyses that certify restricted programs.","remaining_difference":"It addresses confidentiality and information flow generally, not preservation of qualitative provenance, consent restrictions, and interpretive context through a staged transformation pipeline.","source_ids":["H4C2"]},{"name":"PROV validation plus policy-as-code","similarity":"Provides terminating checks for restricted provenance structures and established pre-operation policy evaluation with non-Boolean or undefined outcomes.","remaining_difference":"These mechanisms validate records or declared operations, not whether arbitrary scripts semantically preserve every required link and restriction across all executions.","source_ids":["H4C1","H4C6"]}],"overlapping_components":["Pre-execution policy checking","Restricted declarative policy or workflow language","Provenance representation and consistency validation","Design-time model checking","Sound conservative information-flow analysis","Consent or usage-policy enforcement","Redaction and privacy-aware transformations","Explicit undefined or unsupported outcomes","Human responsibility for non-guaranteed qualitative outputs"],"remaining_contrastive_claim":"No opened source implements, specifically for qualitative-data transformation programs, a pre-installation router that combines a formally justified unrestricted-verification boundary with guarantee-labeled verified-DSL, sound-abstraction, bounded-test, and human-escalation paths while categorically withholding an exact-safe label from unrestricted code.","claim_falsifier":"A paper, product manual, standard, or patent would falsify the claim if it documented such a router for transcription, coding, redaction, or export scripts—including the unrestricted semantic-verification boundary, at least the stated fallback classes and their guarantee labels, and an enforced rule that unrestricted programs cannot receive exact-safe clearance.","problem_support":"WEAK","recommendation":"RESEARCH","world_novelty_boundary":"This bounded eight-query, eight-source search found the mathematical boundary and nearly every implementation component as established work in information-flow security, provenance validation, workflow model checking, usage control, and policy-as-code; it did not find their claimed qualitative-specific, guarantee-labeled routing integration, but it also found little evidence that qualitative platforms currently make the universal script-safety claim the hypothesis is designed to correct."}